Basic terms Flashcards
Compare NSX-T with NSX-V
NSX-T
decoupled from VCenter
Supports : ESXI, KVM, Bare Metal, Kubernetes, AWS and Azure
supports containers
Standalone Solution
can point to VCenter in order to register hosts
NSX manager and controller are on the same appliance
Uses GENEVE for encapsulation
NSX-V VCenter based has NSX manager registered with VCenter Separate appliances for NSX manager and NSX Controller Uses vSphere distributed switch Uses VXLAN for encapsulation
NSX Management
Control Plane
Data Plane
Management Plane
Three Nodes cluster of three virtual appliances
user interface
desired configuration to device
Control Plane
provided by the same NSX management cluster
dynamic state of logical routing, distributed firewall
it learns topology information and pushes it down to data plane
Date Plane VMs Containers NSX Edge Nodes NSX Transport Nodes
NSX Manager Roles
Policy
Manager
Controller
NSX Manager Cluster VIP
Each of the nodes in the management cluster has a dedicated IP but they are managed by a VIP that points to one Node at a time (Leader Node)
NSX Manager Database
A distributed shared database to ensure all information is synchronized between all devices in the cluster. Replicated and distributed.
NSX Controller Functions
Logical Switching
Logical Routing
Distributed Firewall
CCP and LCP
CCP and LCP
CCP
Central control plane that exists on the NSX manager and pushes information to the local control plane that exists on nodes.
NSX Controller Plane Shrading
Each Transport Node is controlled by one NSX Controller in the NSX Management cluster.
Preparing Transport Nodes for NSX-T - Data Plane
On
Hypervisors
Bare Metal Servers
Transport Zone
NVDS
TEPS
VIBs
MPA
Management Plane Agent
retrieves status of distributed firewall
retrieves statistics from Host
NSX-T Segment
Similar to VLAN Identifies a layer 2 segment Spans multiple transport nodes Like a distributed port group on vSphere Identified by a VNI
Distributed Router
Used to route traffic between multiple segments
Spans multiple Transport Nodes
Exists on Edge Nodes
Distributed Firewall
Applies firewall rules directly on the VM Level
ARP Request without NSX
ARP Request with NSX
Without NSX you can’t have a layer 2 network that spans a layer 3 network. A router will drop the ARP broadcast.
NSX allows layer 2 extension by using the concept of overlay and underlay.
GENEVE and TEP
VMkernel port
payload - IP -MAC - VNI - IP - MAC
VNI used to identify the segment that is dropping the frame into the correct Segment aka Correct Logical Switch
Transport Zones
Identifies the scope of an NSX network
A collection of transport nodes that are connected by the GENEVE overlay
When created an N-VDS will be created Two types: Overlay transport zone each transport node can be a member of one the overlay part of the network
VLAN transport zone
used with endpoints we connect directly to vlan backed distributed group
supports 802.1q